Saltar al contenido
05 · Arquitectura05 · Architecture

Preparación para Criptografía Post-CuánticaPost-Quantum Cryptography Readiness

Inventario criptográfico y hoja de ruta hacia algoritmos resistentes.Cryptographic inventory and roadmap towards quantum-resistant algorithms.

NIST FIPS 203/204/205NIST FIPS 203/204/205 Diseño y despliegue de tecnología de seguridadDesign and deployment of security technology

¿Qué es este servicio?What is this service?

Es el trabajo de preparación para el día en que la criptografía actual deje de proteger: levantar el inventario criptográfico de la organización —qué algoritmos, qué claves, qué certificados y en qué sistemas—, evaluar el riesgo por tipo de dato y trazar la hoja de ruta de migración hacia los algoritmos resistentes a computación cuántica.

Preparation work for the day current cryptography stops protecting: building the organisation's cryptographic inventory — which algorithms, which keys, which certificates and in which systems — assessing risk by data type and laying out the migration roadmap towards quantum-resistant algorithms.

¿Para qué se usa?What is it used for?

El riesgo real no está en el futuro sino en el presente, y se llama cosechar ahora y descifrar después: el atacante captura y guarda hoy el tráfico cifrado de la organización, sabiendo que dentro de unos años podrá abrirlo. Si la información sigue siendo sensible dentro de diez o quince años —expedientes médicos, secretos industriales, contratos, datos de estado— el problema ya es de hoy. El NIST publicó los estándares FIPS 203, 204 y 205, así que la migración dejó de ser especulación.

The real risk is not in the future but in the present, and it is called harvest now, decrypt later: the attacker captures and stores the encrypted traffic of the organisation today, knowing it can be opened in a few years. If that information remains sensitive ten or fifteen years from now — medical records, industrial secrets, contracts, state data — the problem is already a present one. NIST published standards FIPS 203, 204 and 205, so migration has stopped being speculation.

Qué beneficios traeBenefits it delivers

  • El inventario criptográfico tiene valor inmediato, aunque nunca llegue la computación cuántica: casi siempre aparecen algoritmos ya rotos y certificados caducados en producción.
  • Permite priorizar por vida útil del dato en lugar de migrar todo a la vez, que ni es posible ni tiene sentido.
  • Da posición defendible ante clientes y reguladores que ya empezaron a preguntar por esto en los cuestionarios de proveedor.
  • Evita la compra por miedo: con inventario en mano se sabe qué hace falta y qué no, y se descarta al proveedor que vende urgencia.
  • The cryptographic inventory pays off immediately, even if quantum computing never arrives: broken algorithms and expired certificates in production almost always turn up.
  • It allows prioritising by data lifetime rather than migrating everything at once, which is neither possible nor sensible.
  • It gives a defensible position with clients and regulators who have started asking about this in vendor questionnaires.
  • It avoids fear-driven purchasing: with an inventory in hand it is clear what is needed and what is not, and the vendor selling urgency can be dismissed.

¿En qué momentos es obligatorio?When is it mandatory?

Costa RicaCosta Rica

  • No hay ninguna obligación en Costa Rica sobre criptografía post-cuántica.
  • Sí hay obligación de proteger los datos personales bajo la Ley 8968, y la protección se evalúa contra el estado del arte, que es justamente lo que está cambiando.
  • There is no obligation in Costa Rica regarding post-quantum cryptography.
  • There is an obligation to protect personal data under Law 8968, and protection is judged against the state of the art, which is precisely what is shifting.

InternacionalInternational

  • Todavía ningún marco de cumplimiento exige migrar, pero los estándares de referencia ya existen: FIPS 203, 204 y 205.
  • ISO 27001 exige una política de uso de controles criptográficos y de gestión de claves, y esa política es donde entra este trabajo.
  • Varios organismos internacionales publicaron horizontes de migración, y los cuestionarios de terceros ya incluyen la pregunta.
  • No compliance framework requires migration yet, but the reference standards already exist: FIPS 203, 204 and 205.
  • ISO 27001 requires a policy on the use of cryptographic controls and key management, and that policy is where this work belongs.
  • Several international bodies have published migration horizons, and third-party questionnaires already include the question.

Requisitos mínimosMinimum requirements

  • Acceso a los sistemas para inventariar certificados, bibliotecas criptográficas y protocolos en uso, incluidos los internos que nadie mira.
  • Un criterio de negocio sobre cuánto tiempo debe seguir siendo confidencial cada tipo de información. Sin eso no hay prioridad posible.
  • El inventario de proveedores y de productos de terceros, porque buena parte de la migración les corresponde a ellos y no a la organización.
  • Aceptar que el primer entregable es un inventario y una hoja de ruta, no un cambio de algoritmos. Quien ofrezca migrar todo de una sola vez está vendiendo humo.
  • Access to systems in order to inventory certificates, cryptographic libraries and protocols in use, including the internal ones nobody looks at.
  • A business view on how long each type of information must remain confidential. Without it, no prioritisation is possible.
  • The inventory of suppliers and third-party products, because much of the migration falls to them rather than to the organisation.
  • Accepting that the first deliverable is an inventory and a roadmap, not an algorithm swap. Anyone offering to migrate everything at once is selling smoke.

Plazo típico de entregaTypical delivery time

8 a 16 semanas 8 to 16 weeks rango habitual del mercado usual market range

El rango habitual va de ocho a dieciséis semanas para el inventario criptográfico, el análisis de riesgo por vida útil del dato y la hoja de ruta. Cae en el extremo bajo cuando el entorno es mayoritariamente nube y hay pocos sistemas propios. Sube al alto con desarrollo interno, aplicaciones antiguas y dispositivos donde la criptografía viene fijada de fábrica. La migración en sí es un programa de varios años, no un proyecto.

The usual range runs from eight to sixteen weeks for the cryptographic inventory, the risk analysis by data lifetime and the roadmap. It lands at the low end in mostly cloud environments with few in-house systems. It rises towards the high end with in-house development, legacy applications and devices where cryptography is fixed in firmware. Migration itself is a multi-year programme, not a project.

NomenclaturaTerminology

Las siglas y estándares que aparecen en esta ficha, explicados. The acronyms and standards used on this page, explained.

PQCPQC
Criptografía post-cuántica: algoritmos diseñados para resistir a una computadora cuántica, ejecutándose en computadoras normales. Post-quantum cryptography: algorithms designed to resist a quantum computer, running on ordinary computers.
Harvest now, decrypt laterHarvest now, decrypt later
Guardar hoy el tráfico cifrado que se intercepta, para descifrarlo cuando exista la capacidad de romperlo. Storing intercepted encrypted traffic today, to decrypt it once the capability to break it exists.
FIPS 203 · 204 · 205FIPS 203 · 204 · 205
Los estándares publicados por el NIST con los algoritmos seleccionados para cifrado de clave pública y firma digital resistentes. The standards published by NIST containing the selected quantum-resistant public key encryption and digital signature algorithms.
Inventario criptográficoCryptographic inventory
La lista de qué algoritmo, qué clave y qué certificado usa cada sistema. Es el primer paso, y casi nadie lo tiene. The list of which algorithm, key and certificate each system uses. It is the first step, and almost nobody has it.
Cripto-agilidadCrypto-agility
Diseñar los sistemas para poder cambiar de algoritmo sin reescribirlos. Es el objetivo de fondo del proyecto. Designing systems so the algorithm can be swapped without rewriting them. It is the underlying goal of the project.